9.3

CVSS4.0

CVE-2025-66266 - Insecure SYSTEM Service Permissions in UPSilon2000V6.0 (RupsMon.exe) leading to trivial Local Privi…

The RupsMon.exe service executable in UPSilon 2000 has insecure permissions, allowing the 'Everyone' group Full Control. A local attacker can replace the executable with a malicious binary to execute code with SYSTEM privileges or simply change the config path of the service to a command; starting …

πŸ“… Published: Nov. 26, 2025, 1:16 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-66265 - Insecure permissions in configuration directory (C:\\usr)

CMService.exe creates the C:\\usr directory and subdirectories with insecure permissions, granting write access to all authenticated users. This allows attackers to replace configuration files (such as snmp.conf) or hijack DLLs to escalate privileges.

πŸ“… Published: Nov. 26, 2025, 1:12 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS4.0

CVE-2025-66264 - Unquoted Service path in UPSilon2000V6.0 SYSTEM privilege service

The CMService.exe service runs with SYSTEM privileges and contains an unquoted service path. This allows a local attacker with write privileges to the filesystem to insert a malicious executable in the path, leading to privilege escalation.

πŸ“… Published: Nov. 26, 2025, 1:09 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.9

CVSS4.0

CVE-2025-66263 - Unauthenticated Arbitrary File Read via Null Byte Injection

Unauthenticated Arbitrary File Read via Null Byte Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Null byte injection in download_setting.php allows reading arbitrary files. T…

πŸ“… Published: Nov. 26, 2025, 12:52 a.m. πŸ”„ Last Modified: Dec. 3, 2025, 4:52 p.m.

9.3

CVSS4.0

CVE-2025-66262 - Arbitrary File Overwrite via Tar Extraction Path Traversal

Arbitrary File Overwrite via Tar Extraction Path Traversal in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Tar extraction with -C / allow arbitrary file overwrite via crafted archive. T…

πŸ“… Published: Nov. 26, 2025, 12:50 a.m. πŸ”„ Last Modified: Dec. 3, 2025, 4:51 p.m.

9.9

CVSS4.0

CVE-2025-66261 - Unauthenticated OS Command Injection (restore_settings.php)

Unauthenticated OS Command Injection (restore_settings.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform URL-decoded name parameter passed to exec() allows remote code execution. The…

πŸ“… Published: Nov. 26, 2025, 12:49 a.m. πŸ”„ Last Modified: Dec. 3, 2025, 4:51 p.m.

7.2

CVSS4.0

CVE-2025-66260 - PostgreSQL SQL Injection (status_sql.php)

PostgreSQL SQL Injection (status_sql.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform SQL injection via sw1 and sw2 parameters in status_sql.php. The `status_sql.php` endpoint const…

πŸ“… Published: Nov. 26, 2025, 12:48 a.m. πŸ”„ Last Modified: Dec. 3, 2025, 4:51 p.m.

9.3

CVSS4.0

CVE-2025-66259 - Authenticated Root Remote Code Execution through improper filtering of HTTP post request parameters

Authenticated Root Remote Code Execution via improrer user input filtering in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform in main_ok.php user supplied data/hour/time is passed directly…

πŸ“… Published: Nov. 26, 2025, 12:46 a.m. πŸ”„ Last Modified: Dec. 3, 2025, 4:50 p.m.

7.1

CVSS4.0

CVE-2025-66258 - Stored Cross-Site Scripting via XML Injection

Stored Cross-Site Scripting via XML Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Stored XSS via crafted filenames injected into patchlist.xml. User-controlled filenames are…

πŸ“… Published: Nov. 26, 2025, 12:45 a.m. πŸ”„ Last Modified: Dec. 3, 2025, 4:50 p.m.

9.2

CVSS4.0

CVE-2025-66257 - Unauthenticated Arbitrary File Deletion (patch_contents.php)

Unauthenticated Arbitrary File Deletion (patch_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform The deletepatch parameter allows unauthenticated deletion of arbitrary files…

πŸ“… Published: Nov. 26, 2025, 12:43 a.m. πŸ”„ Last Modified: Dec. 3, 2025, 4:50 p.m.
Total resulsts: 349182
Page 2897 of 34,919
Β« previous page Β» next page
Filters